OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104120

HIGH · CVSS 7.3 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A vulnerability exists in the Fetch Tool component of the mcp-server-fetch and mcp-server-everything products, specifically in the fetch_url function, which is susceptible to server-side request forgery due to improper handling of URL/path arguments. This flaw can be exploited remotely, potentially allowing attackers to access internal resources or perform unauthorized actions on behalf of the server. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104120
Severity
HIGH
CVSS
7.3
EPSS
0.29%

Original NVD Description

A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-everything up to 2026.6.4. Affected is the function fetch_url of the file mcp_server_fetch/server.py of the component Fetch Tool. The manipulation of the argument url/path leads to server-side request forgery. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.